CVE-2025-0640: IDOR in Akinsoft's OctoCloud
Published Sep 2, 2025
·Updated
Authorization Bypass Through User-Controlled Key vulnerability in Akinsoft OctoCloud allows Resource Leak Exposure.
This issue affects OctoCloud: from s1.09.02 before v1.11.01.
Affected Software
1 affected component
Akinsoft OctoCloud>=s1.09.02<v1.11.01
Event History
Sep 2, 2025
CVE Published
via MITRE·11:48 AM
Data Sourced
via MITRE·11:48 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-0640?
CVE-2025-0640 has a medium severity level due to the risk of authorization bypass leading to resource leak exposure.
2
How do I fix CVE-2025-0640?
To fix CVE-2025-0640, upgrade Akinsoft OctoCloud to version 1.11.01 or later.
3
What causes the vulnerability in CVE-2025-0640?
CVE-2025-0640 is caused by an authorization bypass through user-controlled keys in Akinsoft OctoCloud.
4
Which versions of Akinsoft OctoCloud are affected by CVE-2025-0640?
Akinsoft OctoCloud versions from 1.09.02 before 1.11.01 are affected by CVE-2025-0640.
5
What is the impact of exploiting CVE-2025-0640?
Exploiting CVE-2025-0640 can lead to unauthorized access and exposure of sensitive resources.